Junglewise Threat Intelligence

CVE-2015-7755: Juniper ScreenOS improper authentication in SSH and Telnet

CVE-2015-7755 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-10-02

Vendors: Juniper Networks, Juniper.

Executive brief

Juniper ScreenOS, the operating system for NetScreen firewalls, contains a critical vulnerability that allows unauthorized individuals to gain full administrative control over the device. By using a specific hardcoded password, an attacker can bypass normal security checks to log in remotely via SSH or Telnet. This could lead to complete compromise of the network security infrastructure, allowing attackers to monitor traffic, change security rules, or disable the firewall entirely.

Technical details

An improper authentication vulnerability (CWE-287) exists in Juniper ScreenOS due to the presence of a hardcoded administrative password. Remote attackers can exploit this by initiating an SSH or Telnet session and entering the specific unauthorized password to gain full administrative privileges. The vulnerability affects ScreenOS versions 6.2.0r15 through 6.2.0r18 and 6.3.0r12 through 6.3.0r20. This flaw has been observed being exploited in the wild and allows for complete compromise of the device's confidentiality, integrity, and availability without requiring any prior authentication or user interaction. Juniper has released patched versions (e.g., 6.3.0r12b, 6.3.0r21) to address this issue.

Affected products

  • Juniper Networks ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 through 6.3.0r20 (specific maintenance releases)

Timeline

  • 2015-12-17: disclosed: Initial public disclosure of unauthorized code in ScreenOS
  • 2025-10-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog